Device Access Map
The Access Map is a tab on the device page that shows what each AI agent on one machine can reach. Every AI agent the scan agent found (Claude Code, Cursor, Codex, and so on) is drawn with the MCP servers and skills it has configured, and each of those carries its AI risk, its guard result, and whether a policy rule enforces it. A skill that comes back critical stands out on the map before anyone runs it.
The Access Map is a beta feature. It appears only when the Device Access Map beta flag is on for your organization; ask your Willow contact to turn it on. See Beta Features.
Open the Access Map
- Open AI Discovery and select the Devices tab. See The AI Discovery dashboard.
- Open a device, then select the Access Map tab.
From a device's side panel, the Access map icon in its header opens the same tab directly.
The map reflects the device's most recent scan. Until the scan agent reports an AI agent on the device, the tab reads No AI agents discovered on this device.
What it shows
Each AI agent on the device gets its own group (a base camp on the map, a card in the table). For each agent you see:
- The account it is signed in with, when the scan agent reports one. An account outside your company's email domain is flagged as a Personal account, since an agent signed in with a personal email works outside your organization's controls.
- Its MCP servers and skills, sorted with the riskiest first.
- How many need attention and how many are enforced by a policy rule.
Each MCP server and skill carries three signals:
| Signal | What it tells you |
|---|---|
| AI risk | The AI risk band and 0–10 score from Willow's risk assessment, for example High · 7/10, or Not assessed. See How Willow assesses risk. |
| Guards | The result of the last Guard Check: Passed, Guard warning, Blocked by guard, or Not checked. |
| Enforcement | What a policy rule does with it: Blocked, Warn, Force-managed, Managed, Allowed, or no policy. |
A capability needs attention when its AI risk is medium, high, or critical, or its guard check warned or blocked. It is critical when its AI risk is critical or a guard blocked it. Capabilities you already manage through Willow don't count as needing attention.
Filter and search
The toolbar above the map controls what is shown:
- Needs attention or All. The tab opens on Needs attention when anything on the device needs it, and on All otherwise.
- MCPs and Skills toggles show or hide each kind.
- The search box highlights matching agents, MCP servers, and skills on the map, and filters the rows in the table.
- Map or Table switches the view.
The map view
The map draws the device as an isometric landscape: each AI agent is a base camp, and each MCP server and skill it reaches is a block on that camp, with pins for AI risk, guard results, and enforcement.
The overlay picker at the top left colors the blocks by one signal at a time, and the legend explains the colors:
| Overlay | Colors blocks by |
|---|---|
| Attention | Critical, Needs attention, Managed, or No issues. |
| AI risk | Critical, High, Medium, Low, or Not assessed. |
| Guards | Blocked by guard, Guard warning, Passed, or Not checked. |
| Enforcement | Blocked, Warn, Force-managed, Managed, Allowed, or No policy. |
Hover a block to see its AI risk, guard result, and enforcement. Click a camp to fly to it, and click it again to show every camp.
| Control | Action |
|---|---|
| Drag, or the arrow keys | Pan |
Scroll or pinch, or + / − | Zoom |
Shift + drag, or right-drag | Orbit (3D) |
2 / 3 | Switch between 2D and 3D |
Q / E | Rotate 90° |
F | Fit everything |
Esc | Clear focus or exit fullscreen |
The table view
The table lists the same data as one card per AI agent, with its signed-in account, its MCP server and skill counts, and the capabilities grouped under MCP Servers and Skills. Rows that need attention are marked amber, and critical ones red.
Open a capability
Select any MCP server or skill, on the map or in the table, to open its detail panel: its configuration, the file it was found in, its guard check, and its full AI risk assessment with the reasoning behind the score. From there you can Add to Policy Rule, or Add to Gateway to bring it under management.